DisclosureLens
MARYLANDMalwareHealthcareHealthcareCustomer Data InvolvedDelayed DiscoveryHealth (basic)Identity (basic)HighResolved

LIFEBRIDGE HEALTH, INC.

bd_9aba90d5aceb53c5 · schema v1 · pii pii-v1

Severity

High

Discovered

Mar 1, 2018

Filed

May 15, 2018

To disclose

11 weeks

Affected

538,127

Linked

5 filings

Confidence

94%
Full breach record for LIFEBRIDGE HEALTH, INC.3 incidents on file

LifeBridge Health, Inc. (MD) reported to HHS OCR on 2018-05-15 a Hacking/IT Incident (malware attack on a network server hosting electronic medical records) affecting 538,127 individuals. An unauthorized person accessed the server on September 27, 2016; the breach was not discovered until March 2018. PHI involved included demographic and clinical information. OCR reviewed compliance with Privacy and Security Rules and obtained assurances of corrective actions, including increased password controls and contingency/disaster-recovery procedures.

HIPAA clockDiscovered Mar 1, 2018Notified May 15, 2018 HHS notified11 weeks discovery → filing
unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.

Incident timeline

undetected · 520 days
discovery → filing · 11 weeks / 75 days

Sep 27, 2016

Begins

Mar 1, 2018

Discovered

May 15, 2018

Filed

vs. sector median

2 wks faster

This filing is one of 5 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (4) · sorted by filing gap

Filing propagation · 5 filings · 5 states

View merged incident ↗
California State AGMay 15 · first
Massachusetts State AGMay 15 · first
Montana State AGMay 15 · first
New Hampshire State AGMay 15 · first
HHS OCRMay 15 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.